AWS Certified SysOps Administrator SOA-C01 – Question871

A company in a highly regulated industry has just migrated an Amazon EC2 based application to AWS. For compliance reasons, all network traffic data between the servers must be captured and retained.
Which solution will accomplish this with the LEAST amount of effort?

A.
Set up AWS CloudTrail on the VPC. Configure Amazon CloudWatch Logs as the destination.
B. Set up AWS CloudTrail on the VPC. Configure Amazon S3 as the destination.
C. Set up flow logs at the elastic network interface level. Configure Amazon S3 as the destination.
D. Set up flow logs at the VPC level. Configure Amazon S3 as the destination.